OpenAI names Astra as its first model at the Critical cybersecurity threshold

On 1 September OpenAI said its next major model, Astra, is the first it has designated as meeting the Critical cybersecurity threshold under its own preparedness framework, and that access will start with a small alpha group. No release date, model sizes, context window, API identifier, pricing or safety card accompanied the announcement — a capability was named, a product was not shipped.

What was announced

OpenAI's post on responding to critical cyber capabilities states that Astra is the first model it has designated as meeting the Critical cybersecurity threshold under its own preparedness framework, and that the company plans to make it available soon — first to a small alpha tester group.

The described capabilities centre on multi-agent coordination over long-running tasks and gains in agentic coding. OpenAI states it could not rule out cybersecurity capability at a high level under its own safety standard.

What was not announced, which matters as much

The announcement carried no release date, no model sizes, no context window, no API identifier, no pricing and no safety card. A model was named and a capability was claimed; nothing shipped.

That distinction is worth holding onto, because the gap between a capability announcement and a generally available, documented product has repeatedly been months, and procurement decisions made on the announcement rather than the product age badly.

Why an industrial reader should care

Two reasons, neither of them about coding assistants.

  • A vendor declaring its own model critically capable in cybersecurity is a governance event. It signals that the same class of model being sold into enterprise workflows is one the developer considers materially capable of offensive security work.
  • Self-designation is not external assessment. The threshold, the framework and the judgement are all the vendor's own. That is more transparency than the industry offered two years ago and it is not the same as an audit.

For a plant evaluating agentic AI, the practical question is unchanged and unglamorous: what can the agent reach, what can it change, and who approves that. Capability announcements do not alter the answer.

Sources

Verified 2 September 2026. This story is live and details may change; the announcement did not include product documentation.

All journal entries →